Skip to content

Lab 02 — AI-Assisted Policy Review and Gap Analysis

Welcome to:

Lab 02 — AI-Assisted Policy Review and Gap Analysis

In the previous lab, you performed an AI-assisted enterprise risk assessment.

Now you will move from:

Risk

to:

Policy

Your mission is to review an existing enterprise security policy and determine whether it is:

Clear
Complete
Consistent
Traceable
Actionable
Governable

You will use AI as a:

Policy Analysis Assistant

but every policy conclusion must be validated by you.

You have joined:

CloudNova Technologies

as a:

Cybersecurity
GRC Analyst

CloudNova recently completed an internal risk assessment.

Several risks identified during that assessment relate to:

Privileged Access
Critical Vulnerabilities
Cloud Storage
Security Monitoring
Disaster Recovery
Third-Party Access

Management has now asked the GRC team to review the organization’s:

Information Security Policy

The policy was created several years ago and has received only minor updates.

Your task is to determine whether the policy provides sufficient governance for CloudNova’s current environment.

CloudNova operates a business-critical SaaS platform hosted primarily in AWS.

The organization has:

200 Employees
45 Engineers
12 Cloud Administrators
3 Security Engineers
1 GRC Analyst

The platform processes:

Customer Information
Application Data
Authentication Data
Business Records
System Logs

CloudNova relies on:

AWS
Corporate Identity Provider
Managed Service Provider
Security Monitoring Tools
Vulnerability Management Tools

The existing security policy was originally written when CloudNova had a significantly smaller technology environment.

The GRC team believes several sections may now be:

Outdated
Ambiguous
Incomplete
Inconsistent

By completing this lab, you will learn how to:

  • review the structure of an enterprise policy.

  • distinguish policy statements from standards and procedures.

  • extract policy requirements using AI.

  • identify mandatory and advisory language.

  • identify ambiguous policy wording.

  • identify missing governance elements.

  • identify outdated policy content.

  • compare policy requirements against enterprise risks.

  • map policy requirements to controls.

  • perform policy gap analysis.

  • identify policy-to-control coverage gaps.

  • distinguish policy gaps from implementation gaps.

  • draft policy improvements.

  • maintain traceability to original policy language.

  • validate AI-generated recommendations.

  • prepare an executive policy review summary.

Before starting, you should understand:

Policy
Standard
Control
Procedure
Requirement
Risk
Evidence
Gap

You should also have completed:

04 — AI-Assisted Policy and Standards Management

and preferably:

Lab 01 — AI-Assisted Enterprise Risk Assessment

You may use:

Generative AI Assistant
Spreadsheet Software
Markdown / Text Editor

By the end of this lab, create:

01 Policy Inventory
02 Original Security Policy
03 Policy Requirement Register
04 Policy Quality Review
05 Policy Gap Register
06 Policy-to-Risk Mapping
07 Policy-to-Control Mapping
08 Policy Improvement Register
09 Updated Policy Draft
10 Policy Review Validation
11 Executive Policy Review Summary

For this lab, use the following fictional CloudNova Information Security Policy.

Create:

Original_Information_Security_Policy.md

and copy the following content.

CloudNova is committed to protecting company and customer information from unauthorized access and misuse.

This policy applies to employees who use company systems.

Users should receive access appropriate to their jobs.

Administrator access should be protected using strong security.

Access should be reviewed regularly.

Unused accounts should be removed when appropriate.

Users must use secure passwords.

Passwords should be changed periodically.

Administrators should use stronger passwords where possible.

Systems should be kept secure.

Security updates should be installed regularly.

Critical systems should receive additional protection.

Cloud resources should be securely configured.

Sensitive data should not be made public unless required for business purposes.

Important systems should generate logs.

Security teams should review logs regularly.

Systems should be scanned for vulnerabilities.

Critical vulnerabilities should be resolved quickly.

Sensitive information should be protected.

Encryption should be used when appropriate.

Important information should be backed up.

Recovery processes should be tested periodically.

Vendors should maintain appropriate security controls.

Vendor access should be reviewed when necessary.

Security incidents should be reported to the security team.

The organization should respond appropriately.

Exceptions to this policy may be approved when needed.

This policy should be reviewed from time to time.

Part 2 — Understand the Policy Structure

Section titled “Part 2 — Understand the Policy Structure”

Before performing gap analysis, identify what the current policy already contains.

Create:

Policy_Inventory.csv

with:

Section Topic Requirement Present? Notes
1 Purpose Yes High level
2 Scope Yes Limited scope
3 Access Control Yes Ambiguous requirements
4 Passwords Yes Prescriptive but weak
5 System Security Yes Generic
6 Cloud Security Yes Limited cloud governance
7 Logging Yes Undefined coverage
8 Vulnerability Management Yes Undefined remediation time
9 Data Protection Yes Encryption undefined
10 Backup Yes Testing frequency unclear
11 Third Party Yes Limited governance
12 Incident Management Yes High level
13 Exceptions Yes No formal process
14 Review Yes Undefined frequency

Use:

ROLE
Act as a cybersecurity
policy analysis assistant.
INPUT
Use only the supplied
CloudNova Information
Security Policy.
TASK
Identify:
Policy Sections
Mandatory Requirements
Advisory Statements
Roles
Responsibilities
Review Requirements
Exception Requirements
Missing Governance Elements
CONSTRAINTS
Do not invent
organizational requirements.
Do not rewrite
the policy yet.
Mark unclear areas
as:
Needs Review

Compare AI output with the policy.

Confirm:

Did the AI
Extract It
From the Policy?

If not, mark it:

Unsupported

A policy should contain identifiable requirements.

Create:

Policy_Requirement_Register.csv

with:

Req ID Section Requirement Type Clarity Source
POL-REQ-001 3 Users should receive job-appropriate access Advisory/Ambiguous Low Section 3
POL-REQ-002 4 Users must use secure passwords Mandatory Low Section 4
POL-REQ-003 6 Sensitive data should not be public unless required Advisory Medium Section 6
Extract each individual
policy requirement.
For each provide:
Requirement ID
Section
Original Policy Language
Requirement Type
Mandatory / Advisory
Affected Security Domain
Clarity
Potential Ambiguity
Do not rewrite
the requirement.

The policy contains several phrases that may create governance problems.

Examples:

Appropriate
Strong Security
Regularly
When Appropriate
Periodically
Where Possible
Quickly
When Necessary
From Time to Time

Create:

Policy_Ambiguity_Register.csv

with:

ID Section Phrase Why Ambiguous Information Needed
AMB-001 3 Strong security No defined authentication requirement Authentication standard
AMB-002 3 Regularly Frequency undefined Access review frequency
AMB-003 8 Quickly Remediation timeline undefined Vulnerability SLA
AMB-004 10 Periodically Recovery-test frequency undefined DR testing standard
Review the supplied
policy for ambiguous
or non-measurable
language.
Identify phrases such as:
Regularly
Appropriate
Periodically
Where Possible
Quickly
When Necessary
For each provide:
Section
Original Language
Reason It May Be
Difficult to Enforce
Additional Standard
or Definition Needed
Do not automatically
replace the language.

Part 5 — Identify Policy Governance Gaps

Section titled “Part 5 — Identify Policy Governance Gaps”

Now review the overall policy governance model.

Ask whether the policy defines:

Owner
Approver
Version
Effective Date
Review Frequency
Roles
Enforcement
Exception Authority
Document Classification
Related Standards

Create:

Policy_Governance_Gaps.csv

Example:

Gap ID Governance Element Current State Gap
GOV-001 Policy Owner Not identified Missing accountability
GOV-002 Approver Not identified Approval authority unclear
GOV-003 Review Frequency “From time to time” Not measurable
GOV-004 Exception Process Basic statement Approval and expiration undefined
GOV-005 Roles Mostly absent Responsibilities unclear

If you completed Lab 01, use the risks identified there.

For this lab, use these six risks:

RISK-001
Privileged Account Compromise
RISK-002
Critical Vulnerability Exploitation
RISK-003
Cloud Storage Exposure
RISK-004
Inadequate Security Monitoring
RISK-005
Recovery Failure
RISK-006
Third-Party Privileged Access

Create:

Policy_to_Risk_Mapping.csv

Example:

Risk Relevant Policy Section Coverage Gap
RISK-001 Access Control Partial MFA not explicitly required
RISK-002 Vulnerability Management Partial Critical remediation timeline undefined
RISK-003 Cloud Security Partial Public access governance weak
RISK-004 Logging and Monitoring Partial Coverage and monitoring responsibilities unclear
RISK-005 Backup and Recovery Partial DR testing frequency undefined
RISK-006 Third-Party Security Partial Privileged vendor access controls undefined
Compare the six
validated cybersecurity
risks against the
supplied policy.
For each risk identify:
Relevant Policy Section
Policy Requirement
Potential Coverage
Potential Gap
Missing Standard
Human Review Required
Classify coverage as:
Strong
Partial
Weak
No Clear Coverage
Do not modify
the risk ratings.

Part 7 — Identify Missing Policy Requirements

Section titled “Part 7 — Identify Missing Policy Requirements”

Now analyze what is materially missing.

Potential areas include:

MFA
Least Privilege
Privileged Access
Access Approval
Access Review Frequency
Service Accounts
Vulnerability Remediation
Cloud Security Ownership
Encryption Requirements
Logging Coverage
Log Retention
Incident Escalation
Recovery Testing
Vendor Due Diligence
Vendor Privileged Access
Exception Expiration

Use:

ROLE
Act as a GRC
policy gap analysis
assistant.
INPUT
Current Policy
Validated Enterprise Risks
TASK
Identify policy
requirements that may
be missing or
insufficiently defined
to govern the
validated risks.
For each provide:
Risk
Policy Domain
Current Coverage
Potential Missing Requirement
Reason
Recommended Governance Layer:
Policy
Standard
Procedure
Control
CONSTRAINTS
Do not invent
regulatory requirements.
Do not assume
every technical detail
belongs in policy.

Not every missing technical detail belongs in the policy.

For example:

MFA Required
for Privileged Users

may appropriately appear in a:

Security Standard

while the policy may state:

Privileged access
must be protected
using approved strong
authentication controls.

Part 8 — Policy vs Standard vs Procedure

Section titled “Part 8 — Policy vs Standard vs Procedure”

For every identified gap, decide where it belongs.

Create:

Requirement_Layer_Analysis.csv

Example:

Requirement Policy Standard Procedure
Privileged access must be strongly authenticated
MFA required for all privileged human users
Steps to enable MFA
Vulnerabilities must be remediated based on severity
Critical vulnerabilities within defined SLA
Vulnerability remediation workflow
Policy
WHAT
Standard
SPECIFIC REQUIREMENT
Procedure
HOW

Create:

Policy_Gap_Register.csv

with:

Gap ID Domain Existing Language Gap Risk Severity Recommended Action
GAP-001 IAM “Strong security” MFA requirement not defined RISK-001 High Strengthen policy + authentication standard
GAP-002 Vulnerability “Resolved quickly” SLA undefined RISK-002 High Add severity-based remediation standard
GAP-003 Logging “Review logs regularly” Coverage and review requirements unclear RISK-004 High Define enterprise logging requirements

For this lab use:

High
Medium
Low

Do not confuse:

Policy Gap Severity

with:

Enterprise Risk Rating

Part 10 — Map Policy to Enterprise Controls

Section titled “Part 10 — Map Policy to Enterprise Controls”

Use the following fictional controls.

Control ID Control
IAM-001 User access requires approval
IAM-002 Least privilege is enforced
IAM-003 MFA required for privileged users
IAM-004 Privileged access reviewed quarterly
VUL-001 Vulnerabilities scanned regularly
VUL-002 Critical vulnerabilities remediated within approved SLA
CLD-001 Public cloud storage prohibited unless formally approved
LOG-001 Production activity logs enabled
LOG-002 Production logs sent to centralized monitoring
BCM-001 Production databases backed up daily
BCM-002 Disaster recovery restore tested annually
TPRM-001 Critical vendors receive security assessment
TPRM-002 Third-party privileged access is controlled and reviewed

Create:

Policy_to_Control_Mapping.csv

Example:

Policy Section Policy Requirement Control Coverage
Access Control Job-appropriate access IAM-002 Partial
Access Control Strong administrator security IAM-003 Partial
Vulnerability Management Critical issues resolved quickly VUL-002 Partial
Logging Important systems generate logs LOG-001 Strong
Third Party Vendor access reviewed TPRM-002 Partial
Using only the
supplied enterprise
control library:
Map each policy
requirement to
candidate controls.
For each provide:
Policy Requirement
Control ID
Control Description
Coverage
Difference
Potential Gap
Classify:
Strong Candidate
Partial Candidate
No Clear Control
Do not approve
the mapping.

Part 11 — Distinguish Policy Gap from Control Gap

Section titled “Part 11 — Distinguish Policy Gap from Control Gap”

This is important.

Example:

Control IAM-003
Exists

but policy does not clearly require strong authentication.

This is primarily a:

Policy
Traceability Gap

Another example:

Policy Requires
Access Review

but no enterprise control exists.

This may indicate:

Control
Design Gap

Use these categories:

Policy Gap
Standard Gap
Control Gap
Implementation Gap
Evidence Gap
Needs More Information

Create:

Gap_Classification.csv

Current scope:

This policy applies
to employees who use
company systems.

Ask:

What About:
Contractors?
Vendors?
Service Providers?
Temporary Workers?
Cloud Environments?
Third-Party Systems?

Do not automatically expand scope.

Document:

Current Scope
Potentially Missing Population
Reason
Business Decision Required

Current language:

Users should receive
access appropriate
to their jobs.
Administrator access
should be protected
using strong security.
Access should be
reviewed regularly.

Potential problems:

Should
Appropriate
Strong
Regularly

Step 15 — Draft Improved Policy Language

Section titled “Step 15 — Draft Improved Policy Language”

Example:

Access to information
systems must be granted
according to approved
business need and
least-privilege principles.
Privileged access must
be protected using
approved strong
authentication controls.
User and privileged
access must be reviewed
in accordance with
the approved access
control standard.

Notice that detailed frequencies remain in the standard.

Part 14 — Review Vulnerability Management

Section titled “Part 14 — Review Vulnerability Management”

Current language:

Critical vulnerabilities
should be resolved
quickly.

Potential improved policy:

Security vulnerabilities
must be identified,
evaluated and remediated
according to risk and
the approved vulnerability
management standard.

Then the standard defines:

Severity
SLA
Exception
Escalation

Current language:

Cloud resources
should be securely
configured.

Potential improvement:

Cloud resources must
be configured and
maintained according
to approved security
standards.
Public exposure of
sensitive information
must be prohibited
unless formally approved
through the applicable
risk and exception
process.

Current:

Important systems
should generate logs.
Security teams should
review logs regularly.

Potential improvement:

Security-relevant activity
for in-scope systems
must be logged and
made available for
monitoring, investigation
and audit in accordance
with approved logging
and monitoring standards.

Current:

Recovery processes
should be tested
periodically.

Potential improvement:

Business-critical systems
must maintain documented
backup and recovery
capabilities.
Recovery capabilities
must be tested according
to the approved
business continuity
and disaster recovery
standard.

Current:

Vendors should maintain
appropriate security
controls.
Vendor access should
be reviewed when
necessary.

Potential improvement:

Third parties that
access organizational
systems or information
must undergo security
risk assessment
appropriate to the
risk of the relationship.
Third-party access
must be authorized,
restricted, monitored
and periodically reviewed
according to approved
access-control standards.

Current:

Exceptions to this
policy may be approved
when needed.

This does not define:

Who Approves?
Why?
Risk Assessment?
Compensating Controls?
Expiration?
Review?
Exceptions to this
policy must be formally
documented and approved
through the organization's
security exception process.
Exceptions must include:
Business Justification
Risk Assessment
Compensating Controls
where appropriate
Accountable Owner
Expiration or
Review Date

The policy should include metadata.

Create:

Policy_Metadata.md

Example:

Policy ID:
POL-SEC-001
Policy Name:
Information Security Policy
Owner:
TBD
Approver:
TBD
Version:
2.0 Draft
Effective Date:
TBD
Review Frequency:
Annual
Classification:
Internal
Status:
Draft

Use:

TBD

when the scenario does not provide the answer.

Part 21 — Build the Policy Improvement Register

Section titled “Part 21 — Build the Policy Improvement Register”

Create:

Policy_Improvement_Register.csv

with:

Change ID Section Current State Recommended Change Reason Related Risk
CHG-001 Scope Employees only Review broader workforce/third-party coverage Vendor/admin access exists RISK-006
CHG-002 Access Strong security Reference approved strong authentication MFA gap RISK-001
CHG-003 Vulnerability Quickly Reference risk-based remediation standard Critical vulnerability aging RISK-002

Create:

Updated_Information_Security_Policy_Draft.md

Use the following structure:

1 Purpose
2 Scope
3 Roles and Responsibilities
4 Access Control
5 Authentication
6 System Security
7 Cloud Security
8 Logging and Monitoring
9 Vulnerability Management
10 Data Protection
11 Backup and Recovery
12 Third-Party Security
13 Incident Management
14 Exceptions
15 Compliance and Enforcement
16 Review and Maintenance
17 References

Do not overfill the policy with technical details.

Keep:

Policy
High-Level Mandatory Direction

Move technical specifics into:

Standards

and operational steps into:

Procedures
ROLE
Act as an enterprise
information security
policy drafting assistant.
INPUT
Original Policy
Validated Policy Gaps
Approved Improvement
Register
TASK
Prepare an updated
policy draft.
REQUIREMENTS
Preserve valid
existing requirements.
Improve ambiguous
language.
Add validated
missing governance
requirements.
Use high-level
policy language.
Reference standards
for technical details.
CONSTRAINTS
Do not invent
legal requirements.
Do not invent
organizational owners.
Use TBD where
information is unknown.
Do not declare
compliance.

Part 24 — Compare Original and Updated Policy

Section titled “Part 24 — Compare Original and Updated Policy”

Create:

Policy_Change_Comparison.csv

with:

Section Original Updated Change Type Reason
Scope Employees Broader governed population draft Scope enhancement Third-party risk
Access “Strong security” Approved strong authentication Clarification Privileged risk
Vulnerability “Quickly” Risk-based standard Clarification Measurability

Use change types:

Added
Removed
Clarified
Strengthened
Scope Changed
Governance Added

Now challenge the AI.

Use:

Review the proposed
policy improvements.
Identify:
Requirements not
supported by the
provided risks or
policy analysis
Overly Technical
Policy Language
Unsupported Regulatory
Claims
Unnecessary Requirements
Missing Governance Areas
Potential Conflicts
Do not rewrite
the policy.

Create:

Policy_Review_Validation.md

For each AI recommendation document:

Recommendation
Source
Analyst Decision
Accepted / Rejected
Reason

Every material policy improvement should map to at least one of:

Risk
Control
Governance Requirement
Business Requirement

Create:

Policy_Traceability.csv

Example:

Policy Requirement Risk Control Reason
Privileged access must use strong authentication RISK-001 IAM-003 Credential compromise
Critical vulnerabilities require risk-based remediation RISK-002 VUL-002 Exploitation
Third-party privileged access must be controlled RISK-006 TPRM-002 Vendor admin access

Executives do not need every wording change.

They need to know:

What Is Wrong?
Why Does It Matter?
What Should Change?
What Decision
Is Required?
ROLE
Act as an executive
GRC reporting assistant.
INPUT
Use only the
validated policy
review results.
TASK
Prepare a concise
executive summary
covering:
Major Policy Weaknesses
Business and
Risk Impact
High-Priority Changes
Governance Improvements
Standards Needed
Decisions Required
CONSTRAINTS
Do not claim
the organization
is non-compliant.
Do not invent
regulatory requirements.
Do not exaggerate
risk.
The current Information
Security Policy provides
basic coverage across
major security domains
but contains several
ambiguous and outdated
requirements.
The most significant
issues relate to
privileged access,
vulnerability remediation,
security monitoring,
recovery testing and
third-party access.
Several policy statements
use non-measurable terms
such as "regularly",
"quickly" and
"where appropriate",
which make consistent
implementation difficult.
The recommended update
strengthens governance
requirements while moving
detailed technical
expectations into
supporting security
standards.
Management should confirm
policy ownership,
approval authority,
scope and required
supporting standards
before publication.

Based on your review, recommend supporting standards.

Create:

Required_Security_Standards.md

Suggested list:

01 Access Control Standard
02 Authentication Standard
03 Privileged Access Standard
04 Vulnerability Management Standard
05 Cloud Security Standard
06 Logging and Monitoring Standard
07 Encryption Standard
08 Backup and Recovery Standard
09 Third-Party Security Standard
10 Security Exception Standard

Document the lifecycle:

Draft
GRC Review
Security SME Review
Legal / Privacy Review
Where Required
Policy Owner Review
Approval
Publication
Communication
Review

Before completing the lab, verify:

01 Is the purpose clear?
02 Is scope clear?
03 Is ownership defined?
04 Are requirements mandatory where appropriate?
05 Is ambiguous wording reduced?
06 Are technical details kept in standards?
07 Are key risks covered?
08 Are controls traceable?
09 Are exceptions governed?
10 Is review frequency defined?
11 Are roles and responsibilities clear?
12 Are unsupported requirements removed?
13 Are unknown fields marked TBD?
14 Has AI output been validated?
15 Is the policy ready for formal stakeholder review?

Your updated policy should be:

Clear
Governable
Risk-Aligned
Control-Aligned
Measurable Through Standards
Traceable
Human Approved

It should not become a:

50-Page
Technical Configuration
Manual

A professional policy remains high level.

Keep:

01 Original_Information_Security_Policy.md
02 Policy_Inventory.csv
03 Policy_Requirement_Register.csv
04 Policy_Ambiguity_Register.csv
05 Policy_Governance_Gaps.csv
06 Policy_to_Risk_Mapping.csv
07 Requirement_Layer_Analysis.csv
08 Policy_Gap_Register.csv
09 Policy_to_Control_Mapping.csv
10 Gap_Classification.csv
11 Policy_Metadata.md
12 Policy_Improvement_Register.csv
13 Updated_Information_Security_Policy_Draft.md
14 Policy_Change_Comparison.csv
15 Policy_Review_Validation.md
16 Policy_Traceability.csv
17 Required_Security_Standards.md
18 Executive_Policy_Review_Summary.md

You have successfully completed the lab when:

  • the original policy is documented.

  • individual policy requirements have been extracted.

  • mandatory and advisory statements are identified.

  • ambiguous language is documented.

  • governance gaps are identified.

  • policy requirements are compared to enterprise risks.

  • policy gaps are separated from implementation gaps.

  • requirements are mapped to enterprise controls.

  • supporting standards are identified.

  • an improved policy draft has been created.

  • AI-generated recommendations have been challenged.

  • policy changes remain traceable to risk or governance needs.

  • an executive policy review summary is complete.

  1. What is the purpose of an enterprise security policy?

  2. How is a policy different from a standard?

  3. How is a standard different from a procedure?

  4. Why can words such as “regularly” create governance problems?

  5. Why should policy requirements be individually extracted?

  6. What is a policy governance gap?

  7. Why should policy ownership be defined?

  8. Why should exception approval be formalized?

  9. How can enterprise risks help identify policy gaps?

  10. Why does a missing policy statement not automatically mean a missing control?

  11. What is a policy-to-control mapping?

  12. What is the difference between a policy gap and control gap?

  13. What is an implementation gap?

  14. Why should detailed remediation SLAs normally exist in standards rather than high-level policy?

  15. Why should unknown owners be marked TBD rather than invented?

  16. What is policy traceability?

  17. Why should policy scope include appropriate populations?

  18. Why should AI not invent regulatory requirements?

  19. What is the purpose of a policy improvement register?

  20. Why should AI-generated policy changes receive human review?

Policy governance connects:

Business Requirements
Risks
Policy
Standards
Controls
Procedures
Evidence

AI can help:

Extract
Compare
Analyze
Map
Identify Gaps
Draft
Summarize

But:

AI-Identified
Policy Gap
Confirmed Gap

and:

Policy Gap
Control Failure

and:

AI-Drafted
Policy
Approved Policy

The professional workflow remains:

AI
Analyzes
GRC Analyst
Validates
Security / Business
SMEs Review
Policy Owner
Accepts
Authorized Authority
Approves

This lab mirrors activities commonly performed by:

GRC Analysts
Security Governance Analysts
Policy Analysts
Compliance Analysts
Cyber Risk Analysts
Security Assurance Analysts
GRC Consultants

During an interview, you should be able to explain how you:

Reviewed a Policy
Extracted Requirements
Identified Ambiguity
Mapped Risks
Mapped Controls
Separated Policy
from Standards
Documented Gaps
Drafted Improvements
Validated AI Output

The key professional skill is not simply:

Writing
Security Policies

It is understanding how to connect:

Business
Risk
Policy
Control
Implementation

➡️ Next: Lab 03 — Build an AI-Assisted Common Control Framework

In the next lab, you will move from:

Policy Requirements

to:

Enterprise
Controls

You will create a common control library and use AI to analyze requirements across:

ISO/IEC 27001
NIST CSF
SOC 2
PCI DSS

You will learn how to:

Extract Requirements
Normalize Language
Identify Similar Objectives
Design Common Controls
Detect Duplicate Controls
Map Frameworks
Identify Partial Coverage
Build Traceability

Your final portfolio artifacts will include:

Common Control Library
Requirement Register
Framework Crosswalk
Control Mapping Matrix
Duplicate Control Analysis
Control Ownership Register

➡️ Next: Lab 03 — Build an AI-Assisted Common Control Framework